The leads of Five Eyes cybersecurity agencies have recently and emphatically warned that artificial intelligence (AI) is driving rapid changes in cyber risk. Their key message is that frontier AI models will transform defensive and offensive cyber capabilities in mere months, not years.
What should we take away from this latest clarion call?
Much has already been written about the projected, evolving cyberthreat landscape fuelled by AI-enabled vulnerability discovery, exploit chain development and agentic delivery, occurring at scale and with little human intervention or oversight. While there still may be some debate about the ease and effectiveness of these capabilities — still under review by global experts — there is no doubt that this AI trend will compound and intensify the baseline business risks that most organizations currently carry.
For the past decade or so, these cybersecurity agencies have been relentlessly promoting their best advice, guidance, threat intelligence and alerts to network defenders. They have gone from boardroom to boardroom, imploring C-suite executives to see cybersecurity as an integral part of their business risk, to embrace their technical security advisers, to invest in measures most likely to protect their digital crown jewels, and to be ready with a clear plan to respond when a serious cyber incident occurs. They have promoted the implementation of “security-by-design/default” models and called for software bills of materials in the name of information technology transparency and supply chain risk management. In recent years, they have even extended their reach to small and medium enterprises to share curated lists of recommended cybersecurity measures and to conduct public awareness campaigns to arm citizens with basic or better cybersecurity hygiene.
Their message has been constant and loud, but now the Five Eyes cybersecurity leads are sounding the alarm about a fast-approaching “new normal,” soon to arrive on our doorstep even as we wrestle with the already complicated “current normal.” This latest warning signals a step change in the threat environment that requires us to accelerate efforts and rethink our path at the same time.
Much of the rethink must be rooted in the less-discussed part of their call to action: defensive capabilities will also be transformed. If a threat actor can access state-like capabilities through a simple software subscription and deploy them at machine speeds, Canadian system owners and operators must be prepared to also look to AI to help meet the challenges on this encroaching defence horizon. It may take a while to catch up defensively, but it will only be possible to reduce the gap between offence and defence if we use the power of AI to cut through complexity and improve decision making among cyber defenders.
All the standing advice and guidance of our national cybersecurity agencies — the standards, checklists and security measures — are still valid. But the environment we seek to protect now demands continuous, adaptive, real-time customization. First, our interconnected and interdependent networks, as well as the tools that run on them, introduce unprecedented complexity. Second, systems are incrementally altered as a result of technology updates and security patches, daily internal business decisions and process changes. And, lastly, the threat actor is now agentic, automated, sophisticated and swift. Combined, these factors demand a defensive posture that incentivizes the use of AI-enabled cybersecurity tools and services. That said, these tools must themselves be held to account: evaluated before they are trusted, governed so they do not widen the attack surface, and kept under meaningful human oversight for consequential decisions.
Cybersecurity investment has always been a tough sell. We know from too much experience that there is fierce competition for scarce dollars in corporate budgets and that market forces too often win out over “security-by-design/default” guidance. However, there is great opportunity now to leverage AI in the secure development and life cycle of software systems (secure design, vulnerability detection and remediation at build or deployment time) to introduce less vulnerable software into society. In maintaining more secure systems, AI can be a transformative force for more effective, more timely and more comprehensive patching that helps defenders keep pace with emerging threat vectors. Used well, AI amplifies the fundamentals long promoted by the Canadian Centre for Cyber Security — such as asset inventory, configuration and patching — rather than replacing them.
Today, more Canadian organizations can have access to emerging commercial products and services that use AI to generate up-to-date network inventories, assess for vulnerabilities against any number of cybersecurity standards, and propose useful protections and mitigations. Their offerings can significantly enhance resilience and may even help find ways to draw down long-standing risk in legacy systems thought to be prohibitively expensive to address.
The shift may be more obvious and achievable for medium or larger Canadian enterprises that have already invested in cybersecurity best practices, such as national-level critical infrastructure operators. But smaller organizations can also take advantage as new AI-enabled tools and services enter the cybersecurity market. Even Canada’s least mature and most vulnerable organizations — ones that struggle to implement basic cybersecurity practices — can use open-source AI-enabled cyber assistants for advice, customized to their specific needs in a genuinely helpful, “no shame” environment.
We cannot just shudder in the face of the threat. AI must be employed urgently on the defence side of the cybersecurity ledger if we are to seriously contest agentic AI cyber offence. The Five Eyes are throwing down the gauntlet here. We must rethink our approach, shifting it from how we see risk to how we embrace the power of AI to keep pace with tomorrow’s cyberthreats. Our national cyber resilience depends on it.